CVE-2023-39915CWE-232CWE-240
Crashes on parsing certain invalid RPKI objects
High · published September 13, 2023
What it is
NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914.
The record
Technical detail
- CVSS v3.1
- 7.5 · HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00515 · 41.9th percentile
- Weaknesses
- CWE-232 · Improper Handling of Undefined Values; CWE-240 · Improper Handling of Inconsistent Structural Elements
- Published
- 2023-09-13T14:20Z
EPSS history
Timeline